![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 758](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697758.webp)
Standard X.509 v3 Certificate Extensions
758
Netscape Certificate Management System Administrator’s Guide • June 2003
PKIX Part 1 defines one
accessMethod
(
id-ad-caIssuers
) to get a list of CAs that
have issued certificates higher in the CA chain than the issuer of the certificate
using the extension. The
accessLocation
field then typically contains a URL
indicating the location and protocol (LDAP, HTTP, FTP) used to retrieve the list.
The Online Certificate Status Protocol (RFC 2560), available at
http://www.ietf.org/rfc/rfc2560.txt
, defines an
accessMethod
(
id-ad-ocsp
) for using OCSP to verify certificates. The
accessLocation
field then
contains a URL indicating the location and protocol used to access an OCSP
responder that can validate the certificate.
CMS Version Support
Supported since version 4.2. Refer to “AuthInfoAccessExt” on page 508.
authorityKeyIdentifier
OID
2.5.29.35
Criticality
This extension is always noncritical and is always evaluated.
Discussion
The Authority Key Identifier extension identifies the public key corresponding to
the private key used to sign a certificate. This extension is useful when an issuer
has multiple signing keys (for example, due to CA certificate renewal).
The extension consists of either or both of the following:
•
an explicit key identifier (
keyIdentifier
field)
•
an issuer (
authorityCertIssuer
field) and serial number
(
authorityCertSerialNumber
field) identifying a certificate
If the
keyIdentifier
field exists, then it is used to select the certificate with a
matching
subjectKeyIdentifier
extension. If the
authorityCertIssuer
and
authorityCertSerialNumber
fields are present, then they are used to identify the
correct certificate by
issuer
and
serialNumber
.
If this extension is not present, then the issuer name alone is used to identify the
issuer certificate.
PKIX Part 1 requires this extension for all certificates except self-signed root CA
certificates. Where a key identifier has not been previously established, PKIX
recommends that the
authorityCertIssuer
and
authorityCertSerialNumber
fields be specified. These fields permit construction of a complete certificate chain
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...